CVE-2026-25761Patch(super-linter_project / super-linter)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch super-linter_project super-linter systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Super-linter is a combination of multiple linters to run as a GitHub Action or standalone. From 6.0.0 to 8.3.0, the Super-linter GitHub Action is vulnerable to command injection via crafted filenames. When this action is used in downstream GitHub Actions workflows, an attacker can submit a pull request that introduces a file whose name contains shell command substitution syntax, such as $(...). In affected Super-linter versions, runtime scripts may execute the embedded command during file discovery processing, enabling arbitrary command execution in the workflow runner context. This can be used to disclose the job’s GITHUB_TOKEN depending on how the workflow configures permissions. This vulnerability is fixed in 8.3.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • super-linter

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 3 mentions (2026-02-09); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Products
super-linter

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-02-09: 3Mentions · 2026-02-10: 1Mentions · 2026-08-03: 1Patch / Workaround · 2026-02-09: 1Patch / Workaround · 2026-02-10: 1Patch / Workaround · 2026-08-03: 1Technical Details · 2026-02-09: 3Technical Details · 2026-02-10: 102-0902-1008-03
Signal classification2 categories
Patch
360.0%
Disclosure
240.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-093
Disclosure2Patch1
2026-02-101
Patch1
2026-08-031
Patch1
Full discourse5 posts
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-25761: HIGH] Super-linter GitHub Action versions 6.0.0 to 8.3.0 are prone to command injection via crafted filenames. Update to 8.3.1 to mitigate this critical security vulnerability.#cve,CVE-2026-25761,#cybersecurity https://cvefind.com/CVE-2026-25761

    Post summary

    CVE-2026-25761 enables command injection in Super‑linter GitHub Action v6.0.0–8.3.0 via crafted filenames; updating to 8.3.1 mitigates the issue.

    1000081
    583 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25761 Super-linter is a combination of multiple linters to run as a GitHub Action or standalone. From 6.0.0 to 8.3.0, the Super-linter GitHub Action is vulnerable to comman… https://www.cve.org/CVERecord?id=CVE-2026-25761

    Post summary

    The post announces a command‑injection vulnerability affecting Super‑linter GitHub Action versions 6.0.0 to 8.3.0, but provides no exploit code, PoC, patch, or evidence of active exploitation.

    00010199
    56.5K followersView on X
  • المحارب🏆🇦🇪🇪🇬@nike49424
    Patch

    @cybersecurity 🔥 عينة لأبرز 5 ثغرات مفهرسة ومرفقة بالحلول من داخل التقرير: 1. CVE-2025-13952 (مرفق معها ترقيع برلمجي C++ Patch) 2. CVE-2025-68717 (مرفق معها وثيقة ZayedShield Doc) 3. CVE-2026-25761 (تحليل أمني متقدم لعام 2026) 4. CVE-2025-55182 (تأمين الخدمات البنيوية) 5. CVE-2026-21440 (بلاغ

    Post summary

    The tweet highlights five CVEs, providing a patch for CVE-2025-13952 and references to other solutions, but lacks explicit PoC, exploit tools, or details of active exploitation.

    0000048
    52 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    Super-linter users: A command injection flaw (CVE-2026-25761) via crafted filenames could affect your #GitHubActions workflows. Update to mitigate. #infosec #CI_CD https://www.pulsepatch.io/posts/cve-2026-25761-super-linter-command-injection

    Post summary

    The tweet alerts Super‑linter users to a command injection flaw (CVE‑2026‑25761) affecting GitHub Actions workflows and urges them to update to mitigate the issue.

    0000029
    1 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-25761: Shell Hell in Super-Linter: CVE-2026-25761 Super-linter, the popular 'one-linter-to-rule-them-all' GitHub Action, contained a critical Command Injection vulnerability (CVE-2026-25761) in versions prior to 8.3.1. The flaw resided in the... https://cvereports.com/reports/CVE-2026-25761

    Post summary

    The post announces a command‑injection flaw (CVE‑2026‑25761) in Super‑Linter versions before 8.3.1, but provides no PoC, exploit code, or evidence of active exploitation.

    0000047
    27 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsuper-linter_projectsuper-linter---

Explore more